Remove Harnig. Description and removal instructions

 
Title: Harnig

Type: Trojans
Severity scale:Harnig severity is 65  (65 / 100)
 
Harnig is a trojan designed to secretly download and install numerous adware parasites, dialers, backdoors and other trojans. Once executed, it silently installs itself to the system and drops few pests. Then it contacts certain Internet resources and downloads more parasites. Harnig connects a compromised computer to the Internet by dialing a high-cost phone number using a modem. It also changes the web browser's settings and decreases overall Internet security. The trojan is able to terminate some antivirus processes. It automatically runs on every Windows startup.


Harnig properties:
• Changes browser settings
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Harnig removal:

remover for Harnig

Harnig manual removal:

Kill processes:
desktop.exe, dial32.exe, dkdial.exe, kl.exe, mstasks1.exe, mstasks2.exe, paytime.exe, seksdialer.exe, system.exe, tool[X].exe, toolbar.exe, wintime.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wintime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoadSystem={0A323FA1-38DE-44EC-B2FA-4002183C143E}
HKEY_CLASSES_ROOT\CLSID\{0A323FA1-38DE-44EC-B2FA-4002183C143E}
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MinLevel=Code Download
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Safety Warning Level=SucceedSilent
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Security_RunActiveXControls=0x01000000
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Security_RunScripts=0x01000000
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Trust Warning Level=No Security
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MinLevel=Code Download
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Safety Warning Level=SucceedSilent
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Security_RunActiveXControls=0x01000000
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Security_RunScripts=0x01000000
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Trust Warning Level=No Security
Unregister DLLs:
system32.dll

Delete files:
desktop.exe, dial32.exe, dkdial.exe, kl.exe, mstasks1.exe, mstasks2.exe, paytime.exe, seksdialer.exe, system.exe, tool[X].exe, toolbar.exe, wintime.exe, system32.dll
Misc:
[X] is a digit from 1 to 5.

Exact file location:
dial32.exe, dkdial.exe, wintime.exe, system32.dll - C:\Windows\System32 or C:\Winnt\System32
desktop.exe, kl.exe, mstasks1.exe, mstasks2.exe, paytime.exe, seksdialer.exe, system.exe, tool[X].exe, toolbar.exe - C:\Windows or C:\Winnt

Other programs to remove Harnig:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 12/11/05
Information updated: 12/11/05

Additional resources related to Harnig:

Attention: If you know or you have a website or page about Harnig removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Harnig parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites:
Related discussions: